Skip to content
arrow_back
search
E8-RA-ML2.1 bolt ASD Essential Eight

Disable privileged access after 12 months without revalidation

Ensure privileged access is reviewed and renewed annually for continued access.

record_voice_over

Plain language

This control ensures that people with special access to your computer systems regularly prove they still need it. If someone's access isn't reviewed and confirmed every year, it should be turned off. This matters because keeping tabs on who has special access helps stop bad actors from sneaking in unnoticed.

Framework

ASD Essential Eight

Control effect

Proactive

E8 mitigation strategy

Restrict administrative privileges

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2

Official control statement

Privileged access to systems, applications and data repositories is disabled after 12 months unless revalidated.
bolt ASD Essential Eight E8-RA-ML2.1
priority_high

Why it matters

Not disabling privileged access after 12 months without revalidation increases the risk of misuse by former staff and unauthorised privileged activity.

settings

Operational notes

Perform an annual privileged access revalidation; automatically disable privileged accounts that are not revalidated by the 12-month deadline and record approvals.

Mapping detail

Mapping

Direction

Controls